Sierra Password Training 02.22.2023
Table of Contents
- 1 Password Training 02.22.2023
- 1.1 Training Recording
- 1.2 Q & A Section
- 1.2.1 Sierra
- 1.2.2 Pika
- 1.2.3 Prospector
- 1.2.4 General questions
Password Training 02.22.2023
Training Recording
Q & A Section
Sierra
Q: Why does the information in the PIN field in Sierra display like the password is really long?
A: That field is encrypted and it displays longer than the characters in that field.
Q: When creating new records, after you put the PIN in for the first time do you take out the Password Reset field UNLESS the patron sets their own password?
A: Correct, if you want the patron to reset their own password in Pika, you would either remove the Password Reset field in Sierra or set that field to zero. If the patron put in their own password in Sierra, you would put a message in the Password Reset field. For example, you can put a message that the patron set their own password in Sierra and include the date.
Q: The password prompts “use numbers and/or letters”. You mentioned encouraging patrons to use numbers, letters, and symbols. Are symbols definitely acceptable since the prompt doesn’t state that?
A: Yes, most of the symbols should be acceptable to use in a password. There might be cases where a password field might have trouble with ampersands. Marmot suggests that the Sierra password be just as secure as any other password suggestion you see for other online accounts which would include letters, numbers, and symbols.
Q: If a patron is using one of those automatic password randomizing applications that will automatically set their password how does that work with this process?
A: A lot of those systems are browser-based plug-ins or password managers. It works the same as any other account when you log in to Pika in that if you have your password saved. The password manager will autofill the fields with the password the person has saved in that plug-in. In that case, the patron does not have to know their own password because the password manager is maintaining that password for them. Pika will work for a password manager the same way any other online application works with them.
Q: Would this new password requirement also be transferred to the computer managing software that we may have? For example, we use Envisionware so I’m not sure if this is relevant.
A: It depends if a library hosts their own software or if Marmot hosts the software. If a library hosts their own software, like Envisionware, it can have it set to accept or not accept passwords. For libraries with Marmot-hosted software, like Envisionware, Marmot will not be turning on passwords because there are complications that would need to have staff make reservations for patrons. Marmot will not be enabling passwords on PCRes.
Q: Shoutbomb won't be impacted, correct?
A: Correct, Shoutbomb will not be impacted by Sierra passwords.
Pika
Q: Will all Pika catalogs have the message at the top of the screen (You must enter your default password...)? When will that occur?
A: Marmot staff have been working to wordsmith the language for the banners in Pika. Marmot would like to add a banner for all libraries depending on the logic of how your patron records are entered, or your library Pika admins can add a banner for your library. Marmot would like to make the system messages live in concert with the password go-live.
Q: What about those of us who manage homebound patrons and may need to see their reading history?
A: Seeing the reading history is a toggle option. If this is a need for your library, Marmot can enable that feature. Marmot can also provide reading history through a SQL report if there is any interest.
Q: Is there a limit to the number of times a patron can 'guess' their password before they get locked out?
A: No, there is no limit on the number of times a patron can incorrectly enter a password at this time. There is no current structure to limit the number of times a patron can log in incorrectly. They will not be locked out of their account. It is something that Marmot would like to look into but there is no timeframe for this functionality.
Q: If Forget the Password or Reset My Password is used by a patron, what domain will that email come from?
A: It comes from pika@marmot.org
Q: Masquerade Mode question - will we need to enter the patron's last name and library card once in Masquerade Mode or just the library card number?
A: Masquerade just requires the barcode number.
Q: What if the patron does not have an email or uses email to receive the initial password? Do we direct them to reset passwords in Pika?
A: It depends. If the patron does not have an email address associated with their Sierra patron record then you would set a temporary password for them in Sierra and set the Password Reset field to zero or remove it. When the patron attempts to login into Pika, they will be prompted to enter the temporary password and change their password. There is no requirement for an email if they are not using the Reset My Password functionality in Pika. If they attempt to reset their password from the Reset My Password function and they do not have an email in their Sierra patron record then the system will return an error message.
Patron password reset options
If a patron does not have an email address in their Sierra patron record, they can reset their forgotten password by contacting the library to reset to a temporary password or by coming into the library to set their password.
Staff password reset options
If a patron does not have an email address in their Sierra patron record, staff can still set the Password Reset field in Sierra to allow their patrons to log in to Pika to be prompted to change their password. Patrons will need to know the temporary password in order to change it.
Q: If the patron has registered for a new card using the Pika self-registration and needs to come in to get a permanent card after they received that permanent card will they need to reset their password again?
A: They really should not have to reset their password again because the library will update their card number but the password will be set by the patron when they register. So long as you do not change that Password Reset field in Sierra to zero or remove it, they will not be prompted to change the password that they created.
OverDrive
Q: Can a patron save their password in Libby so only add once?
A: It depends. Once they have logged in with their new password they will only be prompted to log in again if something changes. If the patron changes their password in PIka or a staff member changes the password in Sierra, then they would be prompted to login into Libby again.
Q: Will card numbers be remembered or do patrons literally have to punch in their card number and password each time they open up Libby, after 24 hours?
A: This goes back to the password change. If the patron never has to reset their password after the first time, they should not have to log back into Libby again. It’s only once there is a change to their patron record that Libby will require them to reauthenticate within a 24-hour period.
Q: Do CMC login procedures for OverDrive stay the same?
A: Yes, CMC login procedures will stay the same.
Prospector
Q: Could we use the Masquerade mode in Pika to place holds in Prospector?
A: No. Masquerade mode is just for Pika. You would use the Request on Behalf of Patrons for Prospector process to place a hold for a patron in Prospector.
Q: Does the override code precede or follow the card number?
A: The override code precedes the patron card number (/override/entirepatronbarcode)
Q: Is each library branch going to get its own Prospector override code?
A: No. Each library will get its own Prospector override code.
Q: When you say enter in the patron name for Prospector is it the last name or first name or do you need to enter both?
A: Any portion of the name field works with the name field right now. There might be an issue if you only enter part of a hyphenated name.
General questions
Q: If we are telling patrons the introduction of a password is for patron privacy and then any member of staff can access their accounts without passwords, how do you envision patrons responding to that?
A: If the patron can place their own holds, let them place the holds on their own. Do not masquerade as them in Pika, or use the override code in Prospector. It’s an administrator conundrum where an administrator has more access than a normal-level user. Placing holds on behalf of a patron is a service-level functionality for patrons who are not capable of placing their own holds. It is almost like an accessibility feature where staff can handle holds for homebound and other types of patrons. Right now as staff, you have access to all patron information for your library. Right now, patrons trust you with their information knowing that you are not going to be doing anything malicious with it.
Q: A patron who doesn't change their default password will be locked out on July 31 or August 1. This includes new library card holders on July 30, correct? Is there a mandatory time frame for new library cardholders after August 1 to change their password or get locked out?
A: With the lockout, all the default passwords that are generated by Marmot will be randomized because it is a security breach for Marmot to know the passwords for patrons. The functionality of randomizing the passwords on July 31, 2023, is to basically clear out the default passwords. After August 1, we do not plan to implement any functionality to randomize a patron’s password again. From August 1st on Marmot has to lean on libraries and trust that the library's process is implementing secure passwords for their patrons. Marmot is only randomizing once for unchanged default passwords.
Q: Will patrons using the self-check machines now see a prompt to enter their password?
A: SIP2 is an optional function that is used by self-checkout machines to connect to Sierra. Each library is allowed to decide whether or not to have SIP2 password authentication turned on.